Privacy policy
Version of 05.10.2026
Controller
Zugora is operated by Hartmann Association, a registered association based in Zug, Switzerland. You can find our contact details in the legal notice. We process personal data under the Swiss Federal Act on Data Protection (FADP).
Public pages
The public pages set no cookies. Zugora runs on Cloudflare, which creates technically necessary server logs without query strings in addresses; they are deleted after 7 days. To measure reach we use Cloudflare Web Analytics without cookies and without profiling.
Account
For an account we only process what sign-in requires. We store sign-in data separately from all other content, in a dedicated database (Cloudflare D1) located in the EU.
- Your email address, your chosen language and the time and version of your acceptance of the terms of use.
- A verifier of your password. We never store the password itself; the verifier cannot be reversed and is additionally protected with a secret key.
- For each passkey, the public key, a name, the provider identifier and times of use. Biometric data such as your fingerprint or face never leave your device.
- For each session, a rough device label (e.g. "Safari · iPhone"), your IP address truncated to the network, and times. Session keys and security codes are kept only in a non-reversible, cryptographically protected form.
- Security events (such as sign-ins, changed passkeys, failed attempts) with a truncated IP address, and abuse counters in which addresses only appear as a non-reversible verifier.
Purpose
We process this data to provide your account, secure sign-in, prevent abuse and send you security notifications. On the forms for registration, password sign-in and "Forgot your password?", Cloudflare Turnstile checks that a human is using the form.
Cookies in the account area
Only under zugora.ch/app do we set technically necessary cookies: the session cookie (at most 60 days, invalid after 14 days without use), a cookie for intermediate steps of registration and password recovery (at most 30 minutes), a cookie for passkey sign-in (15 minutes) and a cookie for your chosen language (1 year). There are no advertising or tracking cookies.
Emails
We send confirmation codes and security notifications (such as a new passkey, a changed password or a deleted account) via Cloudflare Email Service from our support address. You cannot unsubscribe from these notifications while the account exists.
Retention and deletion
- Unconfirmed registrations are deleted after 24 hours.
- Codes are valid for 15 minutes and deleted after 24 hours.
- Ended and expired sessions are deleted after 7 days.
- Abuse counters are deleted after 24 hours, security events after 180 days.
- You can delete your account yourself at any time under Account › Delete account. Your account, password verifier, passkeys and sessions are then deleted immediately, and you receive a confirmation by email.
- For technical reasons, deleted data may remain in backups for up to 30 days before it is permanently overwritten.
Processors
We use Cloudflare, Inc. (USA) as a processor: for running and delivering the website, the databases, email delivery, Turnstile and Web Analytics. The sign-in database is located in the EU; Cloudflare may also process data in other countries to operate its network. We do not share personal data for advertising.
Your rights
You can request access to your data and its correction or deletion. Please contact us (details in the legal notice). You can also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).